Home / Standards / Federal PQC Requirements
STANDARDS

Federal PQC requirements: where CMMC and FedRAMP stand today

Federal PQC requirements are still taking shape across CMMC, FedRAMP, and a recent Department of War strategy, each moving at a different pace. Neither CMMC nor FedRAMP mandates post-quantum cryptography outright yet, but a June 2026 Department of War strategy is already moving to add PQC requirements to CMMC, with a 2031 deadline for DoW systems.

Check a domain →
CMMC
No federal framework broadly applicable to contractors mandates post-quantum cryptography outright yet, as of September 2026. CMMC and FedRAMP both currently rest on cryptography requirements written before PQC standards existed, but a June 2026 Department of War strategy is already moving to change that for CMMC, with a December 31, 2031 deadline for DoW systems.

What does CMMC require today?

CMMC Level 2 is built on NIST SP 800-171, Revision 2, which includes FIPS-validated cryptography but does not currently prescribe a PQC migration deadline or specific post-quantum algorithms. A June 2026 U.S. Department of War PQC strategy calls for adding PQC to CMMC requirements, with a December 31, 2031 deadline for DoW systems. CMMC’s third-party certification requirement is currently paused pending a Reform Task Force review, the underlying NIST SP 800-171 obligation it’s built on remains in force regardless.

What does FedRAMP require today?

FedRAMP generally requires cryptographic modules validated to FIPS 140 standards. A cloud provider would need FIPS 203 through 205 implemented in FIPS 140-validated modules before deployment, a process that can take years. Some providers are already moving ahead of full validation, for example Cloudflare’s recent FedRAMP High authorization.

How do CMMC and FedRAMP compare on PQC today?

CMMC
FedRAMP
Basis today
NIST SP 800-171 Rev. 2
FIPS 140-validated modules
PQC mandate today
Not yet, proposed for DoW systems
Not yet, pending FIPS 140 validation of FIPS 203–205
Known deadline
December 31, 2031 (DoW systems, proposed June 2026)
None published

Is CMMC certification currently required?

CMMC’s third-party certification requirement is currently paused pending a Reform Task Force review. The underlying NIST SP 800-171 obligation it’s built on remains in force regardless, so contractors shouldn’t treat the pause as a reason to deprioritize the work.

Why is CMMC's PQC requirement pointed at CMMC and not FedRAMP?

CMMC governs defense contractors handling Controlled Unclassified Information, where the Department of War can set its own timeline. FedRAMP governs cloud service providers to federal civilian agencies and is bound to FIPS 140 module validation, a slower, standards-body process it doesn’t control on its own. That’s why a specific PQC deadline has appeared on the CMMC side first. See the PQC Compliance Timeline for how this sits alongside CNSA 2.0 and NIST’s release dates.
Preparing for federal PQC requirements? Check your domain.

What should contractors do before federal PQC requirements become mandatory?

Federal contractors don’t need to wait for a hard deadline to start. Understanding which TLS services you operate and what algorithms they negotiate today is the foundation for any future requirement, since federal PQC requirements will likely layer on top of existing frameworks like CMMC’s NIST SP 800-171 baseline rather than replace them. Starting with a baseline assessment now means you’re not scrambling once a specific deadline or customer requirement lands.


Written by the team behind Anvil Secure.